
GIAC Cloud Security Essentials
Domain 3Objective 2
Secrets Management GCLD Practice Questions (Page 10)
Part of the Identity, Access, and Secrets domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 46–50
- 46
A company uses GitHub Actions to deploy to AWS. They need to pass database credentials to the deployment job without exposing them in the workflow logs. They also want to ensure that only the production deployment workflow can access the production database credentials. What should they do?
Select an answer first - 47
A security analyst notices that a service account is reading a secret every minute, which is unusual. The secrets manager has audit logging enabled. What is the BEST way to determine if this is a security incident?
Select an answer first - 48
A security team wants to reduce the risk of a long-lived database password being compromised. They decide to rotate the password every 30 days. What is the MOST important consideration when implementing automated rotation?
Select an answer first - 49
A cloud application needs to authenticate to a third-party service using an API key. The key is stored in a secrets manager. The application is deployed on virtual machines. What is the recommended way for the application to retrieve the key at runtime?
Select an answer first - 50
Which of the following is a dedicated cloud service specifically designed for centralized secrets management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.